CVE Tools

Magento

433 CVEs tracked. 5 of them are in CISA KEV.

This hub aggregates every CVE we track for Magento, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Magento CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Magento CVEs per month
MonthCVEs
2024-1022
2024-111
2024-120
2025-010
2025-0223
2025-030
2025-044
2025-050
2025-066
2025-070
2025-086
2025-091
2025-105
2025-111
2025-120
2026-010
2026-021
2026-0319
2026-044
2026-0515
2026-060
2026-0714
2026-087
2026-099

Severity

How the 433 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical4811%
  • High15436%
  • Medium21249%
  • Low194%

Latest CVEs

The 15 most recently published vulnerabilities affecting Magento.

  1. CVE-2026-76200Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)9.3
  2. CVE-2026-76201Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)9.3
  3. CVE-2026-77109Adobe Commerce | Incorrect Authorization (CWE-863)8.6
  4. CVE-2026-77110Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)7.6
  5. CVE-2026-77108Adobe Commerce | Incorrect Authorization (CWE-863)7.5
  6. CVE-2026-76202Adobe Commerce | Incorrect Authorization (CWE-863)8.2
  7. CVE-2026-77774Adobe Commerce | Incorrect Authorization (CWE-863)8.6
  8. CVE-2026-77111Adobe Commerce | Incorrect Authorization (CWE-863)8.7
  9. CVE-2026-75650Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)10.0
  10. CVE-2026-48416Adobe Commerce | Incorrect Authorization (CWE-863)7.5
  11. CVE-2026-48414Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)7.7
  12. CVE-2026-48413Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)8.7
  13. CVE-2026-48415Adobe Commerce | Incorrect Authorization (CWE-863)7.6
  14. CVE-2026-48412Adobe Commerce | Incorrect Authorization (CWE-863)2.7
  15. CVE-2026-48411Adobe Commerce | Incorrect Authorization (CWE-863)6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store